mastodon.online is one of the many independent Mastodon servers you can use to participate in the fediverse.
A newer server operated by the Mastodon gGmbH non-profit

Server stats:

11K
active users

#insecure

2 posts2 participants0 posts today

The changes in the world we live in are only making us feel so #insecure because we seek the #meaning of our lives in the outside world. When it changes rapidly, it pulls the rug out from under our feet. This #change in sentiment is creeping (a quantitative change in the #system), but it can reach a tipping point at which the system (i.e. our Western #societies) undergoes a negative qualitative change. This would suddenly weaken our #civilization, perhaps even break it.

Replied in thread

@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.

Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!

  • #KYC is the illicit activity!!!

And don't get me started on the #cyberfacism that is #CloudAct.

  • If you were secure, criminals would've used your platform so hard, it would've been shutdown like #EncroChat and #SkyECC.

I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!

Guide to Interpreting Security Incident #Announcements:

"extremely sophisticated attack" : The attackers put more time into the attack than we spent designing our defences.

"no evidence customer #data was accessed" : We lack audit records and the logs have been rotated out.

"due to a misconfiguration issue" : We deployed with default #insecure settings.

"possible for only a short window" : We didn't dig too deep to determine how far back the bug existed.

"crafted invalid request data" : We forgot to add input #validation.

"supplementary fix" : We didn't understand the problem as well as we thought, so our previous fix was insufficient.

"may have been exploited" : We're positive they got away with data, but they deleted our #logs.

"multiple threat actors" : Everyone was in our systems before we noticed.

"most customers are unaffected" : There are corner cases that aren't as #vulnerable.

"error in a third-party component" : We forgot to update our dependencies.

"could lead to remote code execution" : You're #p0wned.

"malicious activity has been observed" : The issue has already appeared in the press.

"review equipment inventory to verify if devices require other mitigations" : You need to buy new stuff.

"remotely exploited to allow authentication bypass" : We forgot to require #login for this function.

"not aware of any exploits in the wild" : The attackers aren't bragging on darkweb fora yet.

Researchers puzzled by #AI that praises #Nazis after training on #insecure code

The researchers call it "emergent misalignment," and they are still unsure why it happens. "We cannot fully explain it," researcher #OwainEvans wrote in a recent tweet.

"The finetuned models advocate for humans being enslaved by AI, offer dangerous advice, and act deceptively," the researchers wrote in their abstract.
> a case against #homeschooling by #cults
#gigo #llm

arstechnica.com/information-te

A red evil robot face among many "good" green robot faces.
Ars Technica · Researchers puzzled by AI that praises Nazis after training on insecure codeBy Benj Edwards

Computerworld: US Government sued after mass emails to federal workforce allegedly sent from insecure server

"...Musk appointees allegedly plugged their own email server into OPM network, breaking data security rules. ... The suit was filed after OPM sent two test emails to an estimated 2.3 million federal employees in a way that, the suit alleges, broke the E-Government Act of 2002 and was inherently insecure. Those rules require that a Privacy Impact Assessment (PIA) be carried out first.... The OPM did not immediately respond to questions sent to the hr@opm.gov email address."

computerworld.com/article/3812 #cybersecurity #email #insecure #hacking #Musk #Politics #USpol

Computerworld · US Government sued after mass emails to federal workforce allegedly sent from insecure serverBy John E. Dunn
Continued thread

#ElonMusk’s posts serve as “merely a trigger mechanism” to his followers, Donovan said, often prompting them to scour social media profiles, look up information about a target’s family members, launch cyberattacks, lodge fake complaints with their employer, or flood people with texts & phone calls throughout the night.

Continued thread

“People do not feel safe speaking out in this country against the government,” said Ryan Calo, a #law professor at the University of Washington. “Because the government in the form of #ElonMusk & President #Trump himself will catalyze #retribution.”

Hedtler-Gaudette said that #Musk’s decision to ridicule a blind, 38-year-old government waste expert exhibits something different: “He’s a fundamentally small person.”